Lesson 2 of 11 · Foundations · 3 min read

Agentic AI governance: what changes when AI takes actions

In brief

Agentic AI governance applies policy to what an AI agent does, not only what it says: which tools it may call, with what data, under whose authority, and with what record. It needs controls at runtime and evidence from multi-step testing.

By The Charter Desk, Agentic Governance Compare · Published 2026-09-05 · Vendor pages read 5 September 2026 · Editorial assessment

What is different about agents?

A chat assistant produces text. An agent produces actions: it searches, writes to a ticketing system, sends an email, updates a record or calls another agent. The harm a chat assistant can do is mostly in what it says. The harm an agent can do includes what it changes.

That shifts governance in three ways. Policies have to name actions and tools as well as topics. Controls have to sit where the action happens, not only where the answer is shown. Evidence has to cover sequences of steps, because a problem may appear only on the fourth call of a ten-step task.

What does a policy for an agent look like?

A useful agent policy answers concrete questions: which tools may this agent call; which data may it read or send to each tool; which actions need a human approval; what it must do when an instruction arrives inside a document or a web page rather than from the user; and what gets logged. OWASP's Top 10 for LLM Applications includes 'excessive agency' as a named risk, which is a good prompt for writing these limits down.

Where do controls sit?

For agents, the control points are the input (what the user or a retrieved document asks for), the tool call (what the agent tries to do) and the output (what it returns). Pillar Security, for example, says its runtime guardrails block tool manipulation and log every prompt, response and tool call. Alice's WonderFence sits between external-facing AI and its users and intercepts off-policy responses, configured to the customer's own policies. Check on each vendor's pages which of the three points it describes.

Why does testing have to be multi-step?

Agent failures often build up over a conversation: a harmless first request, a second that sets context, a third that exploits it. Single-prompt tests miss this. Look for multi-turn and agentic red teaming, and for retesting after launch, because the agent's tools, prompts and models change. Pillar describes multi-turn agentic red teaming; Lasso lists multi-turn attacks, agent-logic corruption and tool-chain exploitation; Alice's WonderCheck describes ongoing post-launch red teaming with drift and regression detection.

What record should exist for each agent?

For each agent: its owner, its purpose, the tools and data it can reach, the policy that applies, the controls in front of it, the latest test results and the log of what it did. That is the agent's governance file. The platforms on this site cover different parts of it, which the control maps show step by step.